首页> 外文OA文献 >Scalable High-Performance Parallel Design for Network Intrusion Detection Systems on Many-Core Processors
【2h】

Scalable High-Performance Parallel Design for Network Intrusion Detection Systems on Many-Core Processors

机译:多核处理器上网络入侵检测系统的可扩展高性能并行设计

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Network Intrusion Detection Systems (NIDSes) face significant challenges coming from the relentless network link speed growth and increasing complexity of threats. Both hardware accelerated and parallel software-based NIDS solutions, based on commodity multi-core and GPU processors, have been proposed to overcome these challenges. Network Intrusion Detection Systems (NIDSes) face significant challenges coming from the relentless network link speed growth and increasing complexity of threats. Both hardware accelerated and parallel software-based NIDS solutions, based on commodity multi-core and GPU processors, have been proposed to overcome these challenges. This work explores new parallel opportunities afforded by many-core processors for high performance, scalable and inexpensive NIDS. We exploit the huge many-core computational power by adopting a hybrid parallel architecture combining data and pipeline parallelism. We also design a hybrid load balancing scheme, using both ruleset and flow space partitioning. Furthermore, the proposed design leverages particular features of the processor to break the bottlenecks. We have integrated the open source NIDS Suricata into our proposed design and evaluated its performance with synthetic traffic. The prototype exhibits almost linear speedup and can handle up to 7.2 Gbps traffic with 100-bytes packets.
机译:网络入侵检测系统(NIDSes)面临着巨大的挑战,这些挑战来自于网络链路的持续增长速度和威胁复杂性的增加。已经提出了基于商品多核和GPU处理器的硬件加速和基于并行软件的NIDS解决方案,以克服这些挑战。网络入侵检测系统(NIDSes)面临着巨大的挑战,这些挑战来自于网络链路的持续增长速度和威胁复杂性的增加。已经提出了基于商品多核和GPU处理器的硬件加速和基于并行软件的NIDS解决方案,以克服这些挑战。这项工作探索了多核处理器为高性能,可扩展且廉价的NIDS提供的新并行机会。通过采用结合了数据和管道并行性的混合并行体系结构,我们可以利用巨大的多核计算能力。我们还使用规则集和流空间分区设计了一种混合负载平衡方案。此外,提出的设计利用了处理器的特定功能来突破瓶颈。我们已将开源NIDS Suricata集成到我们提出的设计中,并通过综合流量对其性能进行了评估。该原型具有几乎线性的加速性能,并可以处理100字节数据包的高达7.2 Gbps流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号